The company acted after tests indicated Astra may be approaching its highest category for dangerous cybersecurity capabilities.
OpenAI restricted development of its upcoming Astra model by pausing internal work that does not meet stronger security requirements.
The company announced the restrictions after several days of internal testing and expert reviews raised concerns about Astra’s cybersecurity capabilities. OpenAI has not confirmed that the model can perform the advanced attacks it is testing for.
Stronger controls now govern Astra work
OpenAI said Astra development must now take place under stricter controls.
Those controls include isolated testing environments, limits on the networks and software tools Astra can access, stronger protection and encryption for the model’s core files, additional monitoring, and systems that contain the model’s actions during testing.
OpenAI paused internal Astra activity that is not yet protected by the stricter security controls.
The company also added monitoring across Astra applications that can plan and carry out tasks with limited human direction. The monitors examine the model’s internal reasoning and can trigger a security review or interrupt activity considered high risk.
Tests raised concerns about advanced attacks
OpenAI’s highest cybersecurity risk category, called “Critical,” covers models that can independently find and exploit unknown software flaws in many well-protected real-world systems previously.
The category also includes models that can plan and carry out a new cyberattack against a protected target after receiving only a broad goal.
OpenAI said Astra performed strongly enough in preliminary tests that the company is treating this level of capability as a possibility while its evaluation continues. The tests did not establish that Astra can perform either type of attack.
Earlier OpenAI models, including GPT-5.6-Sol, were rated at the lower “High” level for cybersecurity capabilities.
Government agencies will help test Astra
OpenAI plans to work with government agencies and selected AI safety organizations to test Astra’s capabilities.
The company will also give outside testing partners recommended security controls for conducting higher-risk tests. OpenAI did not provide a timeline for completing the evaluation or resuming the paused activities.

